IP Library Granted Patent US 9,680,824
Granted Patent B1
US 9,680,824 · App. 14/705,438 · Granted Jun 13, 2017

Method and system for authentication by intermediaries

Inventors: Robert Stephen Rodgers (Mountain View, CA); William Norman Eatherton (San Jose, CA); Michael John Beesley (Atherton, CA); Stefan Alexander Dyckerhoff (Palo Alto, CA); Philippe Gilbert Lacroute (Sunnyvale, CA); Edward Ronald Swierk (Mountain View, CA); Neil Vincent Geraghty (San Francisco, CA); Keith Eric Holleman (Campbell, CA); Thomas John Giuli (Mountain View, CA); Srivatsan Rajagopal (Cupertino, CA); Paul Edward Fraley (Sunnyvale, CA); Vijay Krishnaji Tapaskar (Palo Alto, CA); Daniel Sergeevich Selifonov (Mountain View, CA); Keith Anthony Low (San Mateo, CA)
Assignee: Skyport Systems, Inc.
H04L63/0838H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,680,824
App. No.
14/705,438
Granted
Jun 13, 2017
Kind
B1
Abstract

A method and system for authenticating applications. The method includes receiving, by a service virtual machine (SVM), a secret from a management service. The SVM is executing on a computing device. The method also includes providing, by the SVM, the secret to an application executing on an application virtual machine (AVM). The AVM is executing on the computing device. The method further includes providing, by the application, the secret to a remote application server in order for the remote application server to authenticate the application.

Claims (34)

1. A method for authenticating applications, comprising:

providing at least one integrity measurement for a computing device to a management service;

after the providing, and upon an integrity confirmation for the computing device, based on, at least in part, a successful verification of the at least one integrity measurement, by the management service:

receiving, by a service virtual machine (SVM) of a server executing on the computing device, a secret from the management service, wherein the SVM is executing on the computing device;

receiving, by the SVM, a request to connect to a remote application server from an application executing on an application virtual machine (AVM) of the server, wherein the AVM is executing on the computing device;

providing, by the SVM, the secret to the remote application server in order for the remote application server to authenticate the application, wherein the secret is not provided to the application.

2. The method of claim 1 , further comprising:

after providing the secret to the remote application server:

receiving, by the SVM, a notification that the remote application server has authenticated the application; and

connecting, by the application, to the remote application server, via the SVM, after the SVM receives the notification.

3. The method of claim 1 , wherein the secret is generated by the management service.

4. The method of claim 1 , wherein the secret is generated by the remote application server and wherein the management service obtains the secret from the remote application server.

5. The method of claim 1 ,

wherein the at least one integrity measurement for the computing device comprises an integrity measurement for a network adapter, generated by a trusted platform module (TPM) of the network adaptor, and

wherein the network adapter is operatively connected to the server, in the computing device.

6. The method of claim 1 , wherein the secret is only valid to authenticate the application executing on the computing device.

7. The method of claim 1 , wherein the secret is only valid for a finite duration.

8. The method of claim 1 , wherein the at least one integrity measurement for the computing device comprises an integrity measurement for the server generated by a trusted platform module (TPM) in the server.

9. A computing device, comprising:

a server configured to provide at least one integrity measurement for the server to a management service for verification of the server, wherein the server comprises:

a service virtual machine (SVM) executing on the computing device and configured to:

upon confirmation of an integrity of the server based on a successful verification of the at least one integrity measurement by the management service:

receive a secret from the management service;

receive a request to connect to a remote application server from an application executing on an application virtual machine (AVM);

provide the secret to the remote application server in order for the remote application server to authenticate the application, wherein the secret is not provided to the application; and

an application virtual machine comprising the application and configured to:

send, to the SVM, the request from the application to connect to the remote application server.

10. The computing device of claim 9 , further comprising:

a network adaptor operatively connected to the server comprising a trusted platform module (TPM) configured to generate at least one integrity measurement of the network adaptor,

wherein the network adaptor is configured to provide the at least one integrity measurement for the network adaptor to the management service prior to the computing device receiving the secret.

11. The computing device of claim 9 , wherein the secret is generated by at least one selected from a group consisting of the management service and the remote application server.

12. The computing device of claim 9 , wherein the secret is only valid to authenticate the application executing on the computing device.

13. The computing device of claim 9 , wherein the secret is only valid for a finite duration.

14. The computing device of claim 9 , wherein the server further comprises a trusted platform module (TPM) configured to generate the at least one integrity measurement for the server.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2018
From: SKYPORT SYSTEMS LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 046985/0381 →
CHANGE OF NAME Recorded Sep 26, 2018
From: SKYPORT SYSTEMS, INC.
To: SKYPORT SYSTEMS LLC
Reel/Frame 047156/0673 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S ADDRESS PREVIOUSLY RECORDED AT REEL: 035959 FRAME: 0377. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 12, 2017
From: RODGERS, ROBERT STEPHEN; EATHERTON, WILLIAM NORMAN; BEESLEY, MICHAEL JOHN; DYCKERHOFF, STEFAN ALEXANDER; LACROUTE, PHILIPPE GILBERT; GERAGHTY, NEIL VINCENT; HOLLEMAN, KEITH ERIC; GIULI, THOMAS JOHN; RAJAGOPAL, SRIVATSAN; FRALEY, PAUL EDWARD; TAPASKAR, VIJAY KRISHNAJI; SELIFONOV, DANIEL SERGEEVICH; LOW, KEITH ANTHONY; SWIERK, EDWARD RONALD
To: SKYPORT SYSTEMS, INC.
Reel/Frame 043059/0826 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2015
From: RODGERS, ROBERT STEPHEN; EATHERTON, WILLIAM NORMAN; BEESLEY, MICHAEL JOHN; DYCKERHOFF, STEFAN ALEXANDER; LACROUTE, PHILIPPE GILBERT; SWIERK, EDWARD RONALD; GERAGHTY, NEIL VINCENT; HOLLEMAN, KEITH ERIC; GIULI, THOMAS JOHN; RAJAGOPAL, SRIVATSAN; FRALEY, PAUL EDWARD; TAPASKAR, VIJAY KRISHNAJI; SELIFONOV, DANIEL SERGEEVICH; LOW, KEITH ANTHONY
To: SKYPORT SYSTEMS, INC.
Reel/Frame 035959/0377 →
Continuity (1)
Provisional Application 61989957 · May 7, 2014